Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Did IDSes detect the SQL worm?

From: Gonzalez, Albert <albert.gonzalez(at)eds.com>
Date: Wed Jan 29 2003 - 14:15:14 EST


RealSecure did pick up the worms activity. Snort didn't because there was no signature at the time of the worm started spreading. Though they did respond very quickly. Our Dragon sensors aren't correctly running, so I can't verify them

Cheers!

        Alberto Gonzalez

-----Original Message-----
From: Todd Heberlein [mailto:todd_heberlein@mac.com] Sent: Tuesday, January 28, 2003 6:42 PM
To: focus-ids@securityfocus.com
Subject: Did IDSes detect the SQL worm?

Much has been made about the fact that the vulnerability exploited by the MS-SQL worm has been known about for six months. So not only should users have been aware of it, but IDS vendors should have been aware of it.

Here is my question: Other than an IDS reporting an unusual amount of traffic to port 1434, did any report the specific nature of the attack?

In other words, did any IDS report that the packet appears to attack a vulnerability identified by CAN-2002-0649?

Thanks,

Do you need help?X

Todd Received on Fri Jan 31 11:07:22 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:08 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library